Avatier

Attack vector

Over-provisioned standing access

Over-provisioned standing access is permission a user holds beyond what the job needs, all the time, whether or not it is in use. It builds up through role changes, one-off grants nobody revoked and copied access profiles. When that account is compromised, the attacker gets every entitlement it collected, not just the ones the person needs today.

Privilege creep and entitlements nobody revoked.

How attackers use it

After getting into any account, attackers map what it can reach and look for leftover rights: an old admin group, access to a finance share from a previous role, or standing privileged access. Each extra entitlement shortens the path to sensitive data or to control of the environment. Over-provisioned accounts let an ordinary compromise turn into a serious one.

What breach letters say

None of the 2,161 California breach filings in the ledger (January 1, 2023 – August 14, 2026) names this vector. That says what notification letters disclose, not how often it happens.

See the Identity Attack Ledger

How to stop it

Enforce least privilege through regular access reviews and certification, with just-in-time elevation instead of standing admin rights. Remove old entitlements automatically when a person changes roles.

Terms under this vector

  • Privilege creep

    Privilege creep is the gradual build-up of access rights a person collects as they change jobs, join projects or cover for colleagues, without old rights being removed.

  • Privilege escalation

    Privilege escalation is gaining more access than an account was meant to have, such as moving from a standard user to an administrator or granting an app broad new permissions.

  • Toxic combination

    A toxic combination is a set of permissions that is safe when split between people but risky when one identity holds all of them, such as creating a vendor and approving its payments.

Threat actors tied to it

Last reviewed Oct 2, 2026